Описание
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
A flaw was found in ASP.NET Core. This vulnerability allows an unauthorized remote attacker to cause a Denial of Service (DoS) by allocating resources without proper limits or throttling. This can lead to the affected system becoming unresponsive or unavailable to legitimate users.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Dev Spaces | devspaces/udi-rhel9 | Not affected | ||
| Red Hat Enterprise Linux 10 | dotnet8.0 | Fixed | RHSA-2026:41893 | 20.07.2026 |
| Red Hat Enterprise Linux 10 | dotnet9.0 | Fixed | RHSA-2026:41895 | 20.07.2026 |
| Red Hat Enterprise Linux 10 | dotnet10.0 | Fixed | RHSA-2026:41897 | 20.07.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | dotnet8.0 | Fixed | RHSA-2026:58566 | 24.08.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | dotnet9.0 | Fixed | RHSA-2026:58567 | 24.08.2026 |
| Red Hat Enterprise Linux 8 | dotnet9.0 | Fixed | RHSA-2026:41899 | 20.07.2026 |
| Red Hat Enterprise Linux 8 | dotnet10.0 | Fixed | RHSA-2026:41900 | 20.07.2026 |
| Red Hat Enterprise Linux 8 | dotnet8.0 | Fixed | RHSA-2026:41901 | 20.07.2026 |
| Red Hat Enterprise Linux 9 | dotnet8.0 | Fixed | RHSA-2026:41894 | 20.07.2026 |
Показывать по
10
Дополнительная информация
Статус:
Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2500189ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation
EPSS
Процентиль: 60%
0.01008
Низкий
7.5 High
CVSS3
Связанные уязвимости
CVSS3: 7.5
ubuntu
2 месяца назад
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVSS3: 7.5
nvd
2 месяца назад
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
EPSS
Процентиль: 60%
0.01008
Низкий
7.5 High
CVSS3